Account information belonging to League of Legends gamers accessed by intruders

Share this article:

Swords, shields and magic were not enough to fend off an attack that compromised tens of thousands of North American accounts for the popular online game League of Legends.

How many victims? More than 120,000.

What type of personal information? First and last names, usernames, email addresses and salted password hashes. Roughly 120,000 transaction records compiled prior to July 2011 were accessed, which contain "hashed" and "salted" credit card numbers.

What happened? Hackers gained access to the North American servers for Riot Games, the League of Legends developer and publisher. 

What was the response? An investigation is ongoing. Riot Games sent emails to affected players, who will be required to change their passwords to stronger ones that are harder to guess. Riot Games is adding new security features, including email verification and two-factor authentication.   

Details: Details were sparse as the investigation is ongoing. Riot Games is just one video game company to be compromised recently – Nintendo, Ubisoft and Konami were hit in July.

Quote: “We are taking appropriate action to notify and safeguard affected players,” said Riot Games CEO Brandon Beck and President Marc Merrill in the post. “We're sincerely sorry about this situation. We apologize for the inconvenience and will continue to focus on account security going forward.”

Source: beta.na.leagueoflegends.com, League of Legends, “Important Security Update and Password Reset,” Aug. 20, 2013.

Share this article:
You must be a registered member of SC Magazine to post a comment.

Sign up to our newsletters

RECENT COMMENTS

FOLLOW US

More in The Data Breach Blog

About 60K transactions possibly affected in Cape May-Lewes Ferry breach

The security of card processing systems relating to food, beverage and retail sales at the Cape May-Lewes Ferry was compromised and payment card data may be at risk.

Arkansas State University-Beebe is investigating a potential breach

Arkansas State University-Beebe is notifying students and employees of a service running on one of its servers that could pose a potential breach to the system.

Unencrypted discs missing, Arizona State Retirement System notifies 44,000

Arizona State Retirement System notifies nearly 44,000 individuals enrolled in dental plans that two unencrypted discs containing their personal information are missing.